Skip to content

Review follow-ups: redact bootstrap source from traces, checkable claims, stricter config, least-privilege release - #26

Merged
Bogzx merged 5 commits into
mainfrom
improve/2026-10-01-review-nits
Oct 1, 2026
Merged

Bogzx merged 5 commits into
mainfrom
improve/2026-10-01-review-nits

Conversation

@Bogzx

@Bogzx Bogzx commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Follow-up to the review of #21–#25. One commit per point.

Why and what changed

  1. Bootstrap source reached Langfuse (ecb096a). Since API: split app.ts into route modules, one Gemini client, remove dead code #22 the rich bootstrap uses the traced client, so its prompts (up to 16 MB of source) and answers were copied into Langfuse traces. Now those generations record only sizes, model settings and token usage. Request-path calls are traced as before. SELFHOSTING says what reaches Langfuse.
  2. Holdout separation wasn't checkable (282493a). holdout.json and heuristic-score.mjs landed in the same commit (e3c7e2c). README, the eval README, holdout.json and baseline.test.ts now call the separation author-attested and say why.
  3. "The floor the Gemini scorer has to beat" (282493a). The Gemini eval hasn't been run. The Try-it section, README, eval README, SELFHOSTING and the scorer's header comment now say "a baseline a model scorer should beat; not compared yet". The landing-page copy of the scorer is re-synced.
  4. "3-min demo" (282493a). I couldn't verify the length: YouTube returned no metadata to the page fetch or the player API. The number is dropped from the hero and the README.
  5. Unknown TRAILHEAD_DEMO_TEAM values (fc4b713). Values like 0 or no used to mean "default". The API now exits at startup naming the allowed values, and fails closed if one appears at runtime.
  6. release.yml (13eb3f3).
    • permissions: {} at the top.
    • The build job has contents: read. Only the release job, which runs no repo code, has contents: write.
    • persist-credentials: false on checkout.
    • @vscode/vsce 3.9.2 pinned as a devDependency instead of fetched with npx.
    • Assets are uploaded only to a draft; a published release makes the job fail instead of --clobbering its files.
  7. No clear compose error without a key (12af697). Nested interpolation is evaluated eagerly (tried), so a one-shot config-check service (the Postgres image's shell) stops docker compose up with a message when there is neither a key nor TRAILHEAD_LLM=offline. The API depends on it via service_completed_successfully.

Verification

Check Result
npm run typecheck / npm run lint / npm audit --audit-level=high exit 0 / 0 / 0
npm test all pass. API 90 (+2 trace tests, +2 demo-team tests)
Integration suite, Postgres 16 40/40
Dashboard build OK
Trace redaction Turning redaction off makes the new test fail (11/12)
TRAILHEAD_DEMO_TEAM=no npx tsx src/index.ts prints the error and exits 1 before connecting
actionlint (1.7.12) on both workflows clean
Release attach step against a stubbed gh no release → create + upload; draft → upload; published → exit 1, no upload
npm ci with npm 10.9 (Node 22) on the new lockfile OK. Lockfile written with npm 11, so the existing libc fields are kept
npm run package (local vsce) builds the .vsix
docker compose 2.35, neither key nor offline up exits 1 with the message; the API never starts
docker compose 2.35, offline / with a key up -d --wait exits 0 with the API healthy, so CI's smoke test is unaffected
Landing page in headless Chromium "Specific" scores 10/10, the button reads "Watch the demo", no "floor" claim

🤖 Generated with Claude Code

Bogdan Truta and others added 5 commits October 1, 2026 13:42
Since #22 the rich bootstrap goes through gemini.ts's traced client, so with
LANGFUSE_* set its prompts (up to 16 MB of the team's source files) and its
answers (summaries that can quote that code) were copied into Langfuse.

tracedGenerate takes `redact`, and generateText (the bootstrap's entry)
sets it: those generations record only the prompt and answer sizes, the
model settings and token usage. Request-path calls (score, coach, improve,
diff) are traced as before. Two tests with a fake trace: a bootstrap call's
source line never reaches the trace (fails with redact off), and a /score
prompt still does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- The held-out set and the rule-based scorer were added in the same commit
  (e3c7e2c), so "written before the rules were frozen, never tuned on" can't
  be verified from history. README, eval README, holdout.json and
  baseline.test.ts now call it author-attested and say why.
- "The floor the Gemini scorer has to beat" (Try-it section, README, eval
  README, the scorer's header comment) implied a comparison that hasn't been
  run. Now: a baseline a model scorer should beat; not compared yet. The
  landing page's copy of the scorer is re-synced (the sync test checks it).
- "Watch the 3-min demo" / "3-minute walkthrough": the video's length could
  not be checked from here (YouTube returned no metadata), so the number is
  dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
`TRAILHEAD_DEMO_TEAM=0` or `=no` silently meant "default", which on a
server without an admin token is "on" — the opposite of what was probably
meant. demo-team.ts now owns the parsing: on/true, off/false, or unset for
the default; index.ts exits at startup with a message for anything else, and
if an unknown value appears anyway (env changed under a running process) the
demo team fails closed. Unit tests for both; checked that
`TRAILHEAD_DEMO_TEAM=no` stops `src/index.ts` before it touches the database.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…hed releases

- permissions: {} at the top; the build job (checkout, npm ci, tests,
  packaging) runs with contents: read, and only the release job, which runs
  no repository code (it downloads the build artifact and calls gh), gets
  contents: write.
- actions/checkout with persist-credentials: false.
- @vscode/vsce 3.9.2 is an exact devDependency of apps/vscode-ext instead of
  an `npx --yes` fetch at release time (lockfile written with npm 11 so the
  existing libc fields stay; `npm ci` with Node 22's npm 10.9 accepts it;
  npm audit --audit-level=high clean).
- Assets are only uploaded to a draft: if the tag's release is already
  published the job fails instead of --clobbering files people may have
  downloaded; a draft (e.g. a re-run) can still be refreshed.

Checked: actionlint clean on release.yml and ci.yml; the attach step run
against a stubbed gh creates+uploads with no release, uploads to a draft,
and exits 1 for a published release; `npm run package` builds the .vsix
with the local vsce.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#23 relaxed GEMINI_API_KEY from `:?` to `:-` so `TRAILHEAD_LLM=offline`
could run without a key; with neither set, the API then restart-looped with
its error in the logs. Compose can't require a variable only when another is
unset (nested `${A:-${B:?}}` is evaluated eagerly — tried), so a one-shot
`config-check` service (the Postgres image's shell, nothing new to pull)
checks it and prints what to set; the API depends on it with
service_completed_successfully.

Checked with docker compose 2.35: neither set → `up` exits 1 naming the fix
and the API never starts; TRAILHEAD_LLM=offline and a key each → `up --wait`
exits 0 with the API healthy (so CI's smoke test is unaffected).

SELFHOSTING.md: the new failure mode and troubleshooting entry; what reaches
Langfuse (rich-bootstrap traces carry sizes and usage only); unknown
TRAILHEAD_DEMO_TEAM values stop the API; "floor" reworded to "baseline".

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
learnloop Ready Ready Preview Oct 1, 2026 1:43pm UTC
polihackwinners-dashboard Ready Ready Preview Oct 1, 2026 1:43pm UTC

@Bogzx
Bogzx merged commit 581b5a1 into main Oct 1, 2026
9 checks passed

This branch was successfully deployed

2 active deployments
Preview – polihackwinners-dashboard — 12af6976 Deployed Oct 1, 2026 by vercel[bot]
Preview – learnloop — 12af6976 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant